🔐 CVE Alert

CVE-2026-81676

UNKNOWN 0.0

Multiple Vulnerabilities in TOOOLS' iSquad

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.

CWE CWE-89
Vendor toools
Product isquad
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for toools isquad

Be the first to know when new unknown vulnerabilities affecting toools isquad are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TOOOLS / iSquad
0 < 22/07/2026

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-toools-isquad

Credits

DylanCV